Designing Basic Enterprise Campus Networks Part 2 — Transcript
Full transcript
- 0:04enterprise campus design
- 0:09as discussed in the previous video the
- 0:11enterprise campus functional
- 0:13area is divided into the following
- 0:15modules so
- 0:16first you've got the campus
- 0:18infrastructure
- 0:20this module includes three layers okay
- 0:23so you've got the building access layer
- 0:25the distribution
- 0:26layer and the campus core layer
- 0:30now you also have the server form edge
- 0:33distribution which is optional okay so
- 0:37this section discusses the design
- 0:40of each of the layers and modules within
- 0:43the enterprise campus and identifies
- 0:46best practices related to the design
- 0:49of each
- 0:53let's start with the relative
- 0:55considerations for the campus design
- 0:58okay or the enterprise campus
- 1:01requirements
- 1:02now as shown here in the table
- 1:05so each enterprise campus module has
- 1:08different requirements
- 1:10okay so for example this table
- 1:12illustrates
- 1:13how modules located closer to user
- 1:16require
- 1:17a higher degree of scalability so that
- 1:20the campus network can be expanded in
- 1:22the future
- 1:23without redesigning the complete network
- 1:27so for example adding new workstations
- 1:31to a network should result in a neither
- 1:35high investment cost nor performance
- 1:39degradation so you've got
- 1:42end users in the building access layer
- 1:44usually do not require
- 1:46high performance or high availability
- 1:49but
- 1:50these features are crucial to the campus
- 1:53core layer
- 1:54and the server farm module
- 1:58now for the price okay
- 2:01the price per port increases with
- 2:04increased performance
- 2:05and availability now for the campus and
- 2:09core
- 2:11okay so it requires a guarantee
- 2:15of higher throughput so that they can
- 2:18handle all traffic flows
- 2:20and not introduce additional delays or
- 2:23drops
- 2:24to the network traffic the edge
- 2:27distribution this does not require the
- 2:30same performance
- 2:32as in the campus core okay so however
- 2:36it can require other requirements or
- 2:38features and functionalities that
- 2:40increase
- 2:41the overall cost
- 2:43[Music]
- 2:47building access layer design
- 2:48considerations so when
- 2:50implementing the campus infrastructures
- 2:53building access layer
- 2:54you have to consider the following
- 2:56questions okay
- 2:58so how many users or host ports
- 3:01are currently required in the wiring
- 3:03closure
- 3:04and how many will it require in the
- 3:07future
- 3:09so our question would be should the
- 3:11switches be
- 3:12fixed or modular configuration
- 3:15okay so next would be how many ports
- 3:20okay so we're talking about the number
- 3:21of ports how many ports are available
- 3:25for end users connectivity at the walls
- 3:28of the building okay how many access
- 3:32switches
- 3:33are not located in the wiring closets
- 3:37what cabling is currently available in
- 3:39the wiring closet and
- 3:40what cabling options exists for opting
- 3:44connectivity so
- 3:47others would be what data link layer
- 3:49performance
- 3:50does the node need what level
- 3:53of redundancy is needed okay so we have
- 3:56performance redundancy the cabling
- 3:59all right so you also have the
- 4:03what is the required link capacity to
- 4:06the building distribution layer switches
- 4:09okay and how will vlans and sdp be
- 4:13deployed so take note
- 4:15that modern day designs supports
- 4:18vlan or the virtual lan and of course
- 4:21you also have the spanning tree
- 4:24implementation or deployment okay so
- 4:28will there be a single vlan or several
- 4:30vlans per access switch
- 4:33or will the vlans on the switch be
- 4:34unique or spread across multiple
- 4:36switches
- 4:38okay so the latter design was common
- 4:42a few years ago but today end-to-end
- 4:44villains
- 4:46also called as the campus-wide villains
- 4:48are not desirable
- 4:50okay so our additional features such as
- 4:54port security multicast traffic
- 4:58the quality of service are disrequired
- 5:02okay now based on the answers of those
- 5:05questions
- 5:06select the devices that satisfies the
- 5:09building access layer requirements
- 5:11okay now the building access layer
- 5:15should maintain the simplicity of
- 5:16traditional land switching
- 5:18with the support of basic network
- 5:21intelligence services
- 5:23and business applications
- 5:28now what's the key point here okay so
- 5:31the following are the best practice
- 5:33recommendations for optimal building
- 5:35access layer design
- 5:37okay so first you have to manage vlan
- 5:40and stp okay so with that you have to
- 5:44limit valence to a single close-up
- 5:45whenever possible
- 5:48so if stp is required then it is
- 5:50recommended to use
- 5:53the rp bsd plus
- 5:56next would be you need to set the trunk
- 5:59to desirable
- 6:01and desirable with negotiate
- 6:04okay so if you want to learn more about
- 6:07vlans
- 6:07so you could go ahead and check the
- 6:09supplementary videos
- 6:11now manually prone unused vlans is also
- 6:15required and then use vtp
- 6:19transparent mode so all of this
- 6:22recovered on our supplementary video so
- 6:25you could check that out
- 6:27next would be manage trunk between
- 6:29switches
- 6:32manage default php or the
- 6:35port aggregation protocol settings
- 6:38okay and of course you have to consider
- 6:40implementing
- 6:41routing in the access layer
- 6:47now for the stp consideration avoid
- 6:50using
- 6:50stp if possible okay
- 6:54so stp is defined in ieee 802.1d
- 6:59avoid requiring any type of stp or
- 7:02including
- 7:03rapid stp okay so or the rstp
- 7:06by design for most deterministic
- 7:09and highly available network topology
- 7:12that is predictable
- 7:13and bounded and has reliably
- 7:16tuned convergence so for example
- 7:20the behavior of layer 2 environments
- 7:23using stp and layer 3 environments using
- 7:26a routing protocol are different
- 7:28under soft failure conditions
- 7:31so when keep alive messages are lost
- 7:33okay
- 7:34so in sdp environment if
- 7:37bridge protocol data units or bpdu are
- 7:39lost
- 7:40the network fails in an open state
- 7:44for wiring traffic with unknown
- 7:46destinations on all ports
- 7:48potentially causing broadcast storms so
- 7:51in contrast
- 7:52routing environment fill closed
- 7:56dropping routing neighbor relationships
- 7:58breaking connectivity and isolating the
- 8:00soft
- 8:01field devices so another reason
- 8:05to avoid using stp is for load balancing
- 8:08if there are two redundant links stp by
- 8:11default uses only one of these links
- 8:13take note
- 8:14okay so while routing protocols by
- 8:16default uses
- 8:18both right
- 8:21so what if sdp is required
- 8:24okay so if stp is required
- 8:29then use rstp with per vlan spanning
- 8:33three
- 8:33plus okay now if you are using cisco
- 8:36devices
- 8:37the cisco rp vst plus implementation is
- 8:40far superior to 802.1 dstp
- 8:45and even the pbsd plus that is
- 8:48we're talking about the convergence
- 8:50perspective
- 8:51okay so it greatly improves the
- 8:54performance
- 8:55because the convergent times for any
- 8:58vlan
- 8:59on which a link comes up and it greatly
- 9:02improves
- 9:03the convergence time compared to
- 9:05backbone fast
- 9:06okay now another thing is
- 9:10you might want to consider the spanning
- 9:12tree toolkit
- 9:13or the cisco stp toolkit okay
- 9:16so those were mentioned in the previous
- 9:18video you still remember the term like
- 9:20port fast
- 9:22okay under port pass you've got a bpdu
- 9:24guard vpdu filtering
- 9:27okay uplink fast backbone fast stp loop
- 9:30guard
- 9:30root guard you've got the pptu skew
- 9:34detection
- 9:35and of course the udld or the
- 9:37unidirectional link detection
- 9:42now for those cisco stp toolkit
- 9:45okay so you've got broadcast so bypass
- 9:48listening learning
- 9:50okay so for access port so uplink passed
- 9:54three to five seconds convergence after
- 9:56link failure
- 9:57back on fast that's convergence by
- 10:01maximum age for indirect failure so some
- 10:04of this
- 10:05are not anymore supported okay so but
- 10:08then portfast
- 10:10okay look guard root guard those are
- 10:13still active
- 10:14okay now for the loop guard it prevents
- 10:18alternate or root port from becoming a
- 10:20designated
- 10:22in the absence of the ppd use
- 10:25now root guard prevents external
- 10:27switches from becoming a root
- 10:30and vpdu guard it disables the port fast
- 10:34enabled port
- 10:35if bpdu is received so if you want to
- 10:38learn
- 10:39more about this cisco stp toolkit again
- 10:43try to visit our supplementary videos
- 10:52trunk considerations so managing trunks
- 10:56between switches so trunks are typically
- 11:00deployed
- 11:01on the interconnection between the
- 11:03building access and the building
- 11:05distribution layers
- 11:07so there are several best practices to
- 11:10implement
- 11:11with regard to trunking okay
- 11:14so you have to consider the trunk
- 11:17mode and encapsulation
- 11:21so as a best practice when configuring
- 11:24trunks
- 11:25set the dynamic trunking protocol or
- 11:28dtp to desirable
- 11:31on one side and of course desirable on
- 11:34the other end
- 11:35so with that is a negotiation option
- 11:38so one side would be undesirable
- 11:42okay so to have the negotiation between
- 11:44the switch
- 11:46okay so you could also set the pruning
- 11:49okay or manually pruning vlans another
- 11:52best practice
- 11:53is to manually prune unused vlans from
- 11:56trunk interfaces
- 11:58to avoid broadcast propagation
- 12:02so cisco recommends not using automatic
- 12:05vlan pruning
- 12:06manual pruning provides air control
- 12:11so as mentioned the campus wide or
- 12:14access layer wide
- 12:15vlans are no longer recommended so vlan
- 12:18pruning is less of an
- 12:19issue than it is used to be
- 12:24next would be the btp transparent mode
- 12:29so vtp transparent mode should be used
- 12:32as
- 12:32best practice because hierarchical
- 12:35network have
- 12:36little need for a shared common vlan
- 12:38database
- 12:40so using vtp transparent mode decreases
- 12:42the potential for operational errors
- 12:46okay next would be trunking on ports
- 12:50so trunking should be disabled on
- 12:53ports to which hosts will be attached
- 12:56so that host devices do not need to
- 12:58negotiate
- 12:59trunk status so this best practice
- 13:03okay it speeds up the port passed
- 13:07and is a security measure to prevent
- 13:09villain happening
- 13:14layer 3 access the distribution
- 13:16interconnection
- 13:18okay so take note from the hierarchy
- 13:21you've got the access this is where the
- 13:23users are connected to
- 13:24and then of course you'll have
- 13:25distribution devices
- 13:28so although it is not widely deployed in
- 13:30the building access layer
- 13:32a routing protocol such as eigrp
- 13:35or ospf when properly tuned
- 13:38can achieve better convergence results
- 13:41than layer 2 and layer 3 boundary
- 13:42hierarchical design
- 13:44that relies on sdp okay now however
- 13:49adding routing does not result in some
- 13:51additional complexities
- 13:53including uplink ip addressing and
- 13:54subnetting and loss of
- 13:57flexibility okay now this figure here
- 14:00illustrates a sample network with layer
- 14:033 routing
- 14:04okay and that is basically
- 14:09on both the axis
- 14:12and the distribution layer okay now in
- 14:15this figure
- 14:16equal cost layer 3 load balancing is
- 14:19performed on all links
- 14:21although eigrp could perform
- 14:24an equal cost load balancing
- 14:27so stp is not running and the first top
- 14:31redundancy protocol such as
- 14:34hsrp or the hot standby
- 14:37router protocol is not required
- 14:41so vlan cannot
- 14:44span across the multi-layer switch
- 14:48so no vlan spanning is possible
- 14:54building distribution layer design
- 14:56consideration
- 14:58now the building distribution layer
- 15:00aggregates the building access
- 15:03okay segment work groups and isolate
- 15:06segments from failures
- 15:07and broadcast storms so this layer
- 15:11implements many policies based on the
- 15:14access lists
- 15:15and quality of service settings so the
- 15:19building distribution layer can protect
- 15:21the campus core network from any impact
- 15:24of building access layer problems
- 15:27by implementing all the organizations
- 15:30policies
- 15:32so when implementing organization
- 15:35policies
- 15:36okay so the building distribution layer
- 15:38considered
- 15:40the following questions so something
- 15:42like
- 15:43how many devices will each building
- 15:46distribution switch
- 15:47handle so other questions
- 15:51uh what type and level of redundancy are
- 15:54required
- 15:55how many uplinks are needed what speed
- 15:58do the uplinks need
- 16:01to be to the building core switches
- 16:04what cabling is currently available in
- 16:07the wiring closet
- 16:08and what cabling options exists for
- 16:11uplink connectivity
- 16:13okay so as network services are
- 16:15introduced
- 16:17it can it can continue to deliver high
- 16:20performance
- 16:21okay so for all its applications such as
- 16:23the video on demand
- 16:25ip multicast or ip telephony
- 16:29so the network designer must pay special
- 16:33attention to the following network
- 16:34characteristics here
- 16:35so first is of course performance so
- 16:38building distribution switches should
- 16:40provide
- 16:41a wire speed performance on all ports
- 16:44so this feature is important because of
- 16:47the building access layer aggregation
- 16:49on one side and high speed connectivity
- 16:52to the compass core module
- 16:53on the other side so future expansions
- 16:56with additional ports or modules can
- 16:59result in an
- 17:00overloaded switch if it is not selected
- 17:03properly
- 17:04so another consideration would be the
- 17:08redundancy
- 17:09okay redundancy or redundant building
- 17:12distribution layer switches and
- 17:13redundant connections to the campus core
- 17:16should be implemented so using
- 17:19equal cost redundant connections to the
- 17:21core supports
- 17:22fast convergence and avoids routing
- 17:26black holes
- 17:27so network bandwidth and capacity should
- 17:30be engineered
- 17:32to withstand node or link failure
- 17:36and the last one would be the
- 17:38infrastructure services
- 17:40so building distribution switches should
- 17:42not only support
- 17:44past multi-layer switching but
- 17:48also incorporate network services
- 17:52such as high availability quality of
- 17:55service
- 17:56security and policy enforcement
- 17:59so expanding and order reconfiguring
- 18:02distribution layer devices
- 18:04must be easy and efficient so these
- 18:07devices must support the required
- 18:10management feature
- 18:16overview of recommended uh practices for
- 18:19building distribution layer
- 18:21so the key point here is the following
- 18:24are the best practice recommendations
- 18:26for optimal building distribution layer
- 18:28design
- 18:29so first you have to use the first half
- 18:31redundancy protocol
- 18:33okay so either you use the hsrp
- 18:37glb or the brrp
- 18:40next would be deploy a layer 3 routing
- 18:43protocols between the building
- 18:44distribution switches
- 18:46and campus core switches
- 18:50okay and last would be if required
- 18:54connect the distribution switches
- 18:57okay so
- 19:00that is it should be connected to
- 19:02support layer to vlan spanning multiple
- 19:05access switches
- 19:06okay so if required building
- 19:09distribution switches should support
- 19:10vlans that span multiple building access
- 19:14layer switches
- 19:19so using the first half redundancy
- 19:21protocol
- 19:23so if layer 2 is used
- 19:26between the building access and the
- 19:28building distribution switches
- 19:31convergence time when a link or node
- 19:34fails depends on the default gateway
- 19:36redundancy and fill over time
- 19:38okay so building distribution switches
- 19:41typically provide
- 19:42high or the first half redundancy which
- 19:45is the default gateway redundancy using
- 19:47either
- 19:48hsrp okay or you also have the glbp or
- 19:53the
- 19:54gateway load balancing protocol and
- 19:57vrrp or the virtual router redundancy
- 20:00protocol
- 20:02so this redundancy allows a network to
- 20:04recover from the failure
- 20:06of the device acting as a default
- 20:08gateway for end nodes
- 20:11on a physical segment okay
- 20:15so uplink tracking should also be
- 20:17implemented with a first half redundancy
- 20:19protocol
- 20:20so basically hsrp vrrp and glb all of
- 20:25those
- 20:25are classified to be in the first half
- 20:28redundancy protocol
- 20:30okay so hsrp or glb timers can
- 20:35reliably tuned to achieve a sub second
- 20:38800 to 900 milliseconds
- 20:42so we're talking about convergence for
- 20:44link
- 20:45or node failure in the boundary between
- 20:48layer 2 and layer 3 in the building
- 20:49distribution layer
- 20:55now how about the recommended practices
- 20:58on the use of layer 3 routing protocols
- 21:01okay so deploying a layer 3 routing
- 21:04protocols between building distribution
- 21:06and campus core switches
- 21:08so routing protocols between the
- 21:10building distribution switches
- 21:12and the campus scores which support past
- 21:15deterministic convergence for the
- 21:18distribution layer across redundant
- 21:19things
- 21:21so convergence based on the up or down
- 21:24state
- 21:26of a point-to-point physical link is
- 21:28faster than
- 21:29timer based non-deterministic
- 21:31convergence
- 21:33so instead of indirect neighbor or route
- 21:36loss detection using hellos
- 21:38and that so physical link loss
- 21:41indicates that a pass is unusable
- 21:46so that means all traffic is routed
- 21:50to the alternative equal cost path
- 21:57okay so build redundant triangle
- 22:00okay so what do we mean by this
- 22:01redundant triangle so i'll have this
- 22:03okay so not the square so for optimum
- 22:07distribution to core layer convergence
- 22:10build redundant triangle not squares
- 22:13that is to take advantage of the equal
- 22:15cost redundant path
- 22:17for the best deterministic convergence
- 22:20so figure four
- 22:22okay our figure model a and figure model
- 22:25b
- 22:26here illustrates the difference okay
- 22:29now on the left okay or
- 22:32on the model a the multi-layer switches
- 22:35are connected redundantly with a
- 22:38triangle
- 22:39of links that have layer three equal
- 22:42cost paths
- 22:43okay now because the links have equal
- 22:46costs
- 22:47they appear in the routing table and by
- 22:49default
- 22:50will be used for load balancing so
- 22:53if one of the links or distribution
- 22:55layer devices fails
- 22:56convergence is extremely fast
- 23:00because the failure is detected in
- 23:01hardware and there is no need for the
- 23:03routing protocol to recalculate a new
- 23:05path
- 23:07so it just continues to use one of the
- 23:10paths
- 23:11already in its routing table so in
- 23:13contrast
- 23:15on this diagram here okay model b
- 23:18only one path is active by default
- 23:22and link or device failure requires the
- 23:24routing protocol to recalculate a new
- 23:26route
- 23:27to convergence
- 23:32layer 3 distribution interconnection
- 23:35so in cisco deployments hsrp is
- 23:38typically used as the default gateway
- 23:40redundancy protocol
- 23:42so vrrp is an internet engineering task
- 23:46force or ietf standards
- 23:48based method of providing
- 23:51default gateway redundancy so if you are
- 23:53using non-cisco devices then you could
- 23:55go ahead and
- 23:56use vrrp instead so
- 24:00more deployments are starting to use the
- 24:02glbp because
- 24:04it supports load balancing on the
- 24:06uplinks
- 24:07from the access layer to the
- 24:09distribution layer
- 24:11okay as well as the first half
- 24:14redundancy and failure protection
- 24:17now on this diagram here this model
- 24:20supports
- 24:21a recommended layer three point to point
- 24:24interconnection between the distribution
- 24:26and the access switches
- 24:29so no vlan span the building access
- 24:32layer switches
- 24:33across the distribution okay
- 24:36so from an stp perspective
- 24:39both access layer uplinks and forwarding
- 24:42and no sd convergence is required if
- 24:44uplink failure occurs
- 24:47all right so the only convergence
- 24:50dependencies are the default gateway
- 24:53and return path route selection across
- 24:56layer 3 distribution
- 24:58to distribution link okay
- 25:02so if layer 3 is used to the building
- 25:05access switch the default gateway
- 25:07is at the multi-layer building access
- 25:10switch
- 25:11and a first half redundancy protocol is
- 25:13not needed
- 25:16so if you want to learn more about this
- 25:18redundancy
- 25:19okay so you could check these
- 25:21supplementary videos
- 25:23okay so topics about fhrp okay
- 25:28that includes hsrp brp
- 25:32glb all under the first half redundancy
- 25:36protocol or the fhrp
- 25:42so layer two distribution
- 25:43interconnection so let's have this
- 25:45alternate here supporting vlans that
- 25:47span multiple building access layer
- 25:48switches
- 25:50so in less than optimal design where
- 25:52vlans span multiple building
- 25:55okay the building distribution switches
- 25:58must be linked
- 25:59by a layer to connection or
- 26:02the building access layer switches must
- 26:04be connected via
- 26:05trunks okay so trunks should be enabled
- 26:09only between switches okay
- 26:13now this design is more complex than
- 26:16when the building distribution switches
- 26:18are interconnected with
- 26:19layer 3 okay so
- 26:22sdp convergence is required if an uplink
- 26:26failure occurs so again
- 26:29as shown in this figure the following
- 26:31are the recommendations for use
- 26:34in the sub-optimal design okay so use
- 26:38rp bsd plus as a version of stp
- 26:43right so provide a layer to link between
- 26:47the two building distribution switches
- 26:50okay so that is to avoid unexpected
- 26:52traffic pass and multiple convergence
- 26:54events
- 26:55so if you choose the load balancing okay
- 27:00be sure to place the hsrp between the
- 27:05or the hsrp primary and the pvsd
- 27:08plus root on the same building
- 27:10distribution layer
- 27:12to avoid using inter distribution switch
- 27:15link
- 27:15for transit
- 27:21campus core design consideration
- 27:25so first low price okay
- 27:28low price per port and high port density
- 27:31can govern switch choice for wiring
- 27:34closet environments
- 27:36but high performance wire rate
- 27:39multi-layer switching drives the campus
- 27:41core design
- 27:43so using the campus core switches
- 27:45reduces the number of connections
- 27:46between the building distribution layer
- 27:48switches
- 27:49and simplifies the integration of the
- 27:51server farm
- 27:53and the enterprise edge modules
- 27:56okay now the compass core switches
- 28:00are primarily focused on wire speed
- 28:03forwarding
- 28:04on all the interfaces and are
- 28:06differentiated by the level of
- 28:07performance achieved
- 28:09per port rather than high port
- 28:12densities so what's the key point here
- 28:16as recommended practice deploy a
- 28:19dedicated campus core
- 28:21layer that is to connect three or more
- 28:25buildings
- 28:26and the enterprise campus okay
- 28:30so compost core switches are typically
- 28:33multi-layer switches or layer 3 switches
- 28:36so using a campus core makes scaling the
- 28:39network easier
- 28:41for example with the campus core
- 28:45new building distribution switches only
- 28:48need connectivity to the core
- 28:50rather than full mesh connectivity to
- 28:52all other building distribution switches
- 28:56okay
- 29:01about large campus multi-layer switch
- 29:04backbone design
- 29:05so we're talking about the compost or
- 29:07large campus design here
- 29:09so for large campus the most
- 29:12flexible and scalable compass core layer
- 29:15consists of dual multi-layer switches
- 29:18as illustrated on this diagram here okay
- 29:22so you've got the reduced multi-layer
- 29:24switch
- 29:26gearing or routing adjacencies
- 29:29so each multi-layer building
- 29:32distribution switch connects to only two
- 29:34multi-layer campus core switches
- 29:37so using a redundant triangle
- 29:39configuration as shown earlier
- 29:42this implementation simplifies any to
- 29:45any connectivity between building
- 29:46distribution
- 29:48and campus core switches and is scalable
- 29:51to an arbitrarily large size
- 29:54it also supports redundancy and load
- 29:57sharing so next would be
- 30:01topology with no spanning three loops
- 30:04so no stp activity exists in the compass
- 30:08core or on the building distribution
- 30:10links to the campus core layer
- 30:13because all the links are layer 3 or
- 30:15routed links
- 30:16so arbitrary topologies are supported by
- 30:19the routing protocol used
- 30:20in the campus correlator because the
- 30:23core is
- 30:23routed it also provides multicast and
- 30:26broadcast
- 30:28control so next one would be
- 30:32improved network services support so
- 30:35multi-layered campus core switches
- 30:37provide
- 30:38better support for intelligent network
- 30:41services
- 30:42than data link layer core switches could
- 30:44support
- 30:45okay now this design maintains two equal
- 30:49cost
- 30:50paths to every destination network so
- 30:52thus recovery from any link failure is
- 30:55fast
- 30:56and load sharing is possible
- 30:59okay so resulting to a higher throughput
- 31:03in the compass core layer
- 31:05so one of the main considerations when
- 31:07using multi-layer switches
- 31:08in the campus core is switching
- 31:10performance
- 31:12okay multi-layer switching requires more
- 31:14sophisticated devices
- 31:16for high speed packet routing
- 31:19so modern layer 3 switches support
- 31:22routing in the hardware
- 31:24even though the hardware might not
- 31:25support all the features
- 31:28so if the hardware does not support a
- 31:29selected feature
- 31:31it must be performed in software
- 31:35this can dramatically reduce data
- 31:37transfer
- 31:38okay so for example access list
- 31:41might not be processed in the hardware
- 31:44if they have too many
- 31:45entries resulting in switch performance
- 31:48degradation
- 31:54small and medium campus design options
- 31:58so a small campus or large branch
- 32:01network might have fewer than 210
- 32:03devices
- 32:04and network servers and workstations
- 32:06might be connected to the same wiring
- 32:08closet
- 32:09or telecommunication closet now because
- 32:12switches in a small campus network
- 32:14design may not require
- 32:15high-end switching performance or much
- 32:18scaling capability in many cases
- 32:21the campus core and building
- 32:22distribution layers can be combined into
- 32:24a single layer
- 32:25as illustrated on this diagram here
- 32:28okay so this is building access
- 32:31switching
- 32:34all right so this design can scale to
- 32:37only few building access layer switches
- 32:40a low-end multi-layer switch provides
- 32:43routing services
- 32:44closer to the end user when multiple
- 32:47vlans exist
- 32:50so for a very small office
- 32:53only low-end multi-layer switch may
- 32:55support
- 32:56the lan access requirements for the
- 32:59entire office
- 33:01okay so for a medium-sized campus with
- 33:04200
- 33:05to 1000 end devices the network
- 33:08infrastructure typically consists of
- 33:10building access layers such as
- 33:12with uplinks to building distribution or
- 33:14campus core multi-layer switches
- 33:16that can support the performance
- 33:18requirements of a medium-sized campus
- 33:21network
- 33:23so if redundancy is required
- 33:27redundant multi-layer switches connect
- 33:30to
- 33:30or connected to the building axis
- 33:32switches providing full link redundancy
- 33:36as shown here in the diagram okay so
- 33:39when
- 33:39when one of this devices here goes down
- 33:43so there is still a connectivity going
- 33:45to your server form
- 33:49edge distribution design so let's talk
- 33:53about the edge distribution at the
- 33:54campus core
- 33:56so as mentioned in the previous video
- 33:58the enterprise edge
- 33:59modules connect to the campus core
- 34:01directly
- 34:02or through an optional edge distribution
- 34:06module
- 34:07okay now the edge distribution
- 34:11multi-layer switches filter
- 34:13and route traffic into the compass core
- 34:16aggregate enterprise edge connectivity
- 34:20and provide advanced services
- 34:24so switching speed is not as important
- 34:27as security
- 34:28in the edge distribution module which
- 34:31isolates and controls
- 34:33access to devices that are located
- 34:36in the enterprise edge module for
- 34:38example
- 34:39servers in an e-commerce okay
- 34:42or public servers in an internet
- 34:44connectivity module
- 34:46so this servers are closer to the
- 34:49external users and therefore introduce
- 34:51a higher risk to the internal campus
- 34:55so to protect the campus core
- 34:58from threats the switches in the edge
- 35:02distribution module must protect the
- 35:03compass from
- 35:05any of the following attacks okay like
- 35:08an authorized access all connections
- 35:11from the edge distribution module that
- 35:14pass through the campus core
- 35:16must be verified against the user
- 35:19and the user's rights okay
- 35:23you also have ip spoofing so ip spoofing
- 35:27is a hacker technique for
- 35:28impersonating the identity of another
- 35:30user
- 35:32by using the user's ip address
- 35:35so denial of service or dos attacks use
- 35:38ib spoofing
- 35:39to generate requests to servers using
- 35:42the stolen ip address as a source
- 35:46you also have this network
- 35:48reconnaissance
- 35:50what is reconnaissance reconnaissance
- 35:52means
- 35:53discovery okay so
- 35:56the network reconnaissance or discovery
- 35:58sends packets
- 36:00into the network and collects responses
- 36:03from the network devices so these
- 36:06responses provide basic information
- 36:09about internal network topology
- 36:13so next would be packet sniffers
- 36:16so packet sniffers are devices that
- 36:18monitor and capture the traffic in the
- 36:20network
- 36:21and might be used by hackers so packets
- 36:25belonging to
- 36:27the same broadcast domain are vulnerable
- 36:30to capture
- 36:30by pocket sniffers okay especially if
- 36:34the packets are broadcast or
- 36:38multicast
- 36:41server placement in a medium-sized
- 36:43network
- 36:45so within the campus network servers may
- 36:47be placed
- 36:48locally in the building access or
- 36:50building distribution layer
- 36:52or attach directly to the campus core
- 36:56now centralized servers are typically
- 36:58grouped into a server farm
- 37:01located in the enterprise campus or in a
- 37:04separate data center
- 37:07so servers directly attached to building
- 37:10access or building distribution layer
- 37:12switches
- 37:15so if a server is local to a certain
- 37:18work group
- 37:19okay that corresponds to one vlan
- 37:22and all workgroup members and the server
- 37:25are attached to the building access
- 37:27layer switch
- 37:28most of the traffic to the server is
- 37:30local to the workgroup
- 37:32so if required an access list at the
- 37:36building distribution layer switch
- 37:38would hide the servers from the
- 37:40enterprise
- 37:41so in some mid-size networks building
- 37:45level servers that communicate with
- 37:47clients in different vlans
- 37:50but that are still within the same
- 37:52physical building
- 37:54can be connected to building
- 37:56distribution layer switches
- 37:58okay so how about servers directly
- 38:02connected to the campus core
- 38:04is that possible well you can do that
- 38:07okay
- 38:07so the campus core generally transports
- 38:10traffic quickly without any limitations
- 38:14so servers in the medium-sized campus
- 38:17can be connected directly to the campus
- 38:19core switches
- 38:21okay so making the servers closer to the
- 38:23users
- 38:25than if the servers were in the server
- 38:27form
- 38:28as shown here in the future
- 38:32now however ports are typically limited
- 38:35in the campus core switches
- 38:37so policy based control qos and access
- 38:40control list or acl
- 38:42for accessing the servers is implemented
- 38:44in the building distribution layer
- 38:46rather than in the campus core
- 38:52how about server placement in a large
- 38:54network
- 38:55okay servers in the server farm module
- 38:59so larger enterprises may have
- 39:03moderate or large server deployments
- 39:06for enterprises with
- 39:09moderate server requirements common
- 39:12servers are located in a separate server
- 39:14form module connected to the compass
- 39:16core
- 39:17using a multi-layer server distribution
- 39:20switches
- 39:22okay now because of a high traffic load
- 39:26the servers are usually gigabit ethernet
- 39:29attached to the server farm switches
- 39:33so access list on the server farm module
- 39:37okay so implements the controlled access
- 39:39to the servers
- 39:41redundant distribution switches in the
- 39:43server farm module
- 39:45and solutions such as the hsrp or glb
- 39:48provides
- 39:50fast failover so the server farm module
- 39:54distribution switches
- 39:56also keep all the server to
- 39:59server traffic of the campus core
- 40:05all right so how about the server farm
- 40:07design guidelines
- 40:09okay so as shown here in the figure
- 40:12the server form can be implemented as
- 40:16high capacity building block attached to
- 40:18the campus core
- 40:19so again you have redundancy of
- 40:21connectivity there okay
- 40:25now one of the main concerns with the
- 40:27server farm module
- 40:29is that it receives the majority of the
- 40:31traffic from the entire campus
- 40:34so random frame drops can result because
- 40:38the uplinks ports on the switches
- 40:41are frequently over subscribed okay
- 40:44so when say switch over subscription it
- 40:47of course when a switch allows
- 40:49more ports or bandwidth in the chassis
- 40:52then switch hardware can transfer
- 40:54through its internal structure
- 40:57right so to guarantee that no random
- 41:01frame jobs occur for business critical
- 41:03applications
- 41:04the network designer should apply the
- 41:06quality of service mechanisms
- 41:09okay now next would be
- 41:14the server connectivity options
- 41:17so servers can be connected in several
- 41:20different ways for example
- 41:22a server farm or a server can attach
- 41:26by one or two fast ethernet connections
- 41:30okay so that's dual and ic redundancy
- 41:34so if the server is dual attached okay
- 41:37or dual nic redundancy
- 41:39one interface can be active while the
- 41:41other is
- 41:42in hot standby
- 41:45now installing multiple single port nic
- 41:48or multi-port and ics
- 41:50in the servers extends dual home
- 41:52rehoming passed
- 41:54the server farm okay so to the server
- 41:57itself
- 41:58so servers needing redundancy can be
- 42:02connected with
- 42:03dual and ic homing in the access layer
- 42:06or at
- 42:07an nic that supports easter channel okay
- 42:11well several other solutions are
- 42:12available
- 42:14to improve server responsiveness
- 42:17and evenly distribute the load to them
- 42:19so we call it
- 42:20load balancing right so that
- 42:23is we have to use okay so our
- 42:27redundant link also to move the data
- 42:30from the source to destination
- 42:32not just using it for backups
- 42:38now to summarize the enterprise campus
- 42:40design
- 42:42design and enterprise campus network
- 42:44using recommended processes
- 42:46so use low price per port
- 42:49and high port density on data link layer
- 42:53switches
- 42:54for building the access layer
- 42:57use redundant multi-layer switching in
- 43:00the building distribution layer
- 43:02for high availability and performance
- 43:06use high performance wire rate
- 43:09multi-layer switching in the compass
- 43:11core design
- 43:12and group centralized servers into
- 43:15server form module
- 43:16for moderate enterprise server
- 43:22requirements
About this transcript
This page contains the full transcript of Designing Basic Enterprise Campus Networks Part 2 by Santelmo, generated from the public captions YouTube serves with the video. The transcript has 4,905 words across 1,021 segments, with the original timestamps preserved so you can click any line to jump to that moment in the embedded player.
What you can do with it
Use the transcript to take notes, quote the speaker, build a study guide, generate a summary with ChatGPT or Claude via the YouTube Summary tool, or export it as a timed subtitle file with YouTube to SRT. You can also re-open it in the transcriber to translate the transcript into 100+ languages.
Free YouTube transcript tool
YouTube2Text is a free YouTube transcript generator — no signup, no daily limit. Paste any YouTube link and get the full transcript instantly, with timestamps, click-to-jump, translation to 100+ languages, AI prompts for ChatGPT, Claude, and Gemini, and exports to TXT, SRT, VTT, or Markdown.